Risk prediction method and apparatus
By acquiring and processing business data, calculating anomaly evaluation parameters and security situation information, the problem of inaccurate risk prediction has been solved, and more accurate network security situation prediction has been achieved.
Patent Information
- Application Number
- CN202311347590.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-17
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2043-10-17
AI Technical Summary
How to improve the accuracy of risk prediction in order to address the economic and security risks posed by cyberattacks.
By acquiring business data collected by preset components, abnormal business data is identified, and the mean, median, and standard deviation are calculated to generate anomaly evaluation parameters. These parameters and security situation information are then used for risk prediction.
By generating risk prediction results for the entire network based on business data characteristics across different dimensions, the accuracy of risk prediction is improved.
Smart Images

Figure CN118797753B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present document relates to the technical field of security, and in particular to a risk prediction method and device. BACKGROUND
[0002] With the development of Internet technology, the amount of data processed by a business system is increasing, and the network responsible for storing business data is also becoming increasingly large. If the network storing business data is subjected to malicious attacks, not only will the network be paralyzed, but the loss and damage of business data can bring huge economic and security risks. If the malicious attacks are discovered in time through risk prediction and corresponding warning measures are taken, the data security of users can be effectively protected. Therefore, how to improve the accuracy of risk prediction is increasingly concerned. SUMMARY
[0003] An embodiment of the present specification aims to provide a risk prediction method and device to solve the problem of how to improve the accuracy of risk prediction.
[0004] To solve the above technical problems, an embodiment of the present specification is implemented as follows:
[0005] In a first aspect, an embodiment of the present specification provides a risk prediction method, comprising:
[0006] obtaining first business data collected by a preset component, and determining abnormal business data collected by the preset component according to the first business data;
[0007] performing mean value calculation processing, median value calculation processing and standard deviation calculation processing on the abnormal business data respectively to obtain abnormal mean value, abnormal median value and abnormal standard deviation of the preset component;
[0008] determining an abnormal evaluation parameter of the preset component according to the abnormal business data, the first business data, the abnormal mean value, the abnormal median value and the abnormal standard deviation;
[0009] determining security posture information of the preset component according to the abnormal evaluation parameter and the first business data;
[0010] performing risk prediction processing on the first business data according to the abnormal evaluation parameter and the security posture information to obtain a risk prediction result.
[0011] In a second aspect, another embodiment of the present specification provides a risk prediction device, comprising:
[0012] a data determination module configured to obtain first business data collected by a preset component, and determine abnormal business data collected by the preset component according to the first business data;
[0013] a data calculation module configured to perform mean value calculation processing, median value calculation processing, and standard deviation calculation processing on the abnormal service data respectively, to obtain abnormal mean value, abnormal median value, and abnormal standard deviation of the preset component;
[0014] a parameter determination module configured to determine abnormal evaluation parameters of the preset component according to the abnormal service data, the first service data, the abnormal mean value, the abnormal median value, and the abnormal standard deviation;
[0015] an information determination module configured to determine security situation information of the preset component according to the abnormal evaluation parameters and the first service data;
[0016] a risk prediction module configured to perform risk prediction processing on the first service data according to the abnormal evaluation parameters and the security situation information, to obtain a risk prediction result.
[0017] In a third aspect, a risk prediction device is provided, which includes a memory, a processor, and computer executable instructions stored in the memory and executable in the processor, and when the computer executable instructions are executed by the processor, the steps of the risk prediction method according to the first aspect are implemented.
[0018] In a fourth aspect, a computer readable storage medium is provided, which is configured to store computer executable instructions, and when the computer executable instructions are executed by a processor, the steps of the risk prediction method according to the first aspect are implemented.
[0019] The risk prediction method provided in the embodiment comprises the following steps: acquiring first service data collected by a preset component, and determining abnormal service data collected by the preset component according to the first service data; performing mean value calculation processing, median value calculation processing and standard deviation calculation processing on the abnormal service data respectively to obtain abnormal mean value, abnormal median value and abnormal standard deviation of the preset component; determining an abnormal evaluation parameter of the preset component according to the abnormal service data, the first service data, the abnormal mean value, the abnormal median value and the abnormal standard deviation; determining security situation information of the preset component according to the abnormal evaluation parameter and the first service data; and performing risk prediction processing on the first service data according to the abnormal evaluation parameter and the security situation information to obtain a risk prediction result. In this way, the abnormal evaluation parameter of the preset component can be generated based on the abnormal service data, the first service data, the abnormal mean value, the abnormal median value and the abnormal standard deviation in the case that different dimensions of service data features collected by different preset components are different, and then the abnormal evaluation parameter is used to convert the service data of different dimensions into the risk prediction result of the whole network in the process of generating the security situation information and using the security situation information to perform risk prediction, thereby improving the accuracy of risk prediction. BRIEF DESCRIPTION OF DRAWINGS
[0020] In order to more clearly illustrate the technical solutions in the one or more embodiments of the present specification, the drawings needed to be used in the embodiments or prior art description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments described in the present specification, and other drawings can also be obtained by those skilled in the art without creative labor.
[0021] Figure 1 A risk prediction method processing flowchart is provided for an embodiment of the present specification.
[0022] Figure 2 A storage cluster structure diagram is provided for an embodiment of the present specification.
[0023] Figure 3 A sub-flowchart for representing how to generate an abnormal evaluation parameter in a risk prediction method is provided for an embodiment of the present specification.
[0024] Figure 4 A sub-flowchart for representing how to generate security situation information in a risk prediction method is provided for an embodiment of the present specification.
[0025] Figure 5 A sub-flowchart for representing how to generate risk prediction weight information in a risk prediction method is provided for an embodiment of the present specification.
[0026] Figure 6Another risk prediction method processing flowchart provided by an embodiment of the present specification;
[0027] Figure 7 A risk prediction device schematic diagram provided by an embodiment of the present specification;
[0028] Figure 8 A structure schematic diagram of a risk prediction device provided by an embodiment of the present specification. DETAILED DESCRIPTION
[0029] In order to make the person skilled in the art better understand the technical scheme in one or more embodiments of the present specification, the technical scheme in one or more embodiments of the present specification will be described clearly and completely in combination with the drawings in one or more embodiments of the present specification. Obviously, the described embodiments are only a part of the embodiments of the present specification, not all the embodiments. Based on one or more embodiments of the present specification, all other embodiments obtained by the person skilled in the art without creative labor should belong to the protection scope of the present document.
[0030] An embodiment of a risk prediction method provided by the present specification:
[0031] Referring to Figure 1 The risk prediction method provided by the present embodiment specifically includes the following steps S102 to S110.
[0032] Step S102, acquiring first business data collected by a preset component, and determining abnormal business data collected by the preset component according to the first business data.
[0033] A component is a simple encapsulation of data and methods. One or more components can be configured in a business system. In the case that the number of components included in the business system is multiple, each component can have different functions.
[0034] The preset component can be a security component, or other component with data collection capability in the business system.
[0035] The number of preset components can be one or multiple.
[0036] In the case that the number of preset components is multiple, each preset component collects business data of different dimensions. The business data of each dimension is data generated in the working process of the business system.
[0037] In particular implementation, for each preset component, the preset component can collect service data of a corresponding dimension according to a preconfigured data collection period, or collect service data of a corresponding dimension when a data collection condition is detected.
[0038] For example, component 1 can collect traffic volume according to period T1, component 2 can collect alarm quantity according to period T2, component 3 can collect error logs when data collection condition 1 is met, and so on.
[0039] The first service data collected by the preset component can be all service data collected by the preset component, which is taken as the first service data.
[0040] The first service data collected by the preset component can also be service data collected based on a preset time length, which is taken as the first service data.
[0041] For example, the preset time length is one month, and the first service data collected by the preset component can be service data collected by the preset component in the last one month, which is taken as the first service data.
[0042] Taking the preset component as a security component, the first service data can be monitoring data collected by each security component.
[0043] For example, monitoring data 1 collected by an intrusion detection component, monitoring data 2 collected by an intrusion prevention component, and monitoring data 3 collected by a network traffic detection component, and so on.
[0044] In addition, in the case of a large amount of service data, the cluster storage technology can be used to distribute the service data of the service system in the storage cluster.
[0045] Cluster storage is to aggregate the storage spaces in multiple storage devices into a storage pool that can provide a unified access interface and management interface for application servers. Applications can transparently access and utilize all the disks on the storage devices through the access interface, which can fully utilize the performance and disk utilization of the storage devices.
[0046] The following can illustrate how to obtain the first service data by combining a structural diagram of a storage cluster. Figure 2 A structural diagram of a storage cluster is provided for an embodiment of the present specification.
[0047] As shown in Figure 2 The service data of the service system can be stored through the storage cluster 200.
[0048] The storage cluster 200 is provided with components 202, 204 and 206. The monitoring data 208 can be collected through the component 202, the monitoring data 210 can be collected through the component 204, and the monitoring data 212 can be collected through the component 206.
[0049] The monitoring data 208, the monitoring data 210 and the monitoring data 212 are three different dimensions of business data obtained by monitoring the storage cluster through the corresponding components.
[0050] The first business data can include a plurality of sub-data.
[0051] According to the first business data, the abnormal business data collected by the preset component can be determined. For each sub-data, the sub-data is compared with the pre-configured business exception threshold value in value size:
[0052] If the sub-data is greater than or equal to the business exception threshold value, it is determined that the sub-data belongs to abnormal business data; if the sub-data is less than the business exception threshold value, it is determined that the sub-data does not belong to abnormal business data.
[0053] Or, if the sub-data is less than the business exception threshold value, it is determined that the sub-data belongs to abnormal business data; if the sub-data is greater than or equal to the business exception threshold value, it is determined that the sub-data does not belong to abnormal business data.
[0054] In the case of collecting the first business data based on the preset time length, if there is no sub-data belonging to abnormal business data in the first business data of a certain preset component, it means that it is relatively safe within this period of time. In the case of obtaining all business data collected by the preset component as the first business data, if there is no sub-data belonging to abnormal business data in the first business data of a certain preset component, it means that all data collected by the preset component represents safety, the preset component has no unsafe impact on the security posture of the entire network, and the first business data of the preset component can be excluded, that is, the data collected by the preset component does not participate in risk prediction.
[0055] In the case of collecting the first business data based on the preset time length, if there is no sub-data belonging to abnormal business data in the first business data of a certain preset component, the first business data is updated, the first business data after the update is compared with the business exception threshold value in value size, and a comparison result is obtained. The abnormal business data is determined based on the comparison result.
[0056] For example, the acquisition component 1 acquires the service data of the last 1 month as the first service data, if each sub-data in the first service data does not belong to the abnormal service data, the preset time length is doubled to reacquire the data, that is, the acquisition component 1 acquires the service data of the last 2 months as the first service data after the update processing, if each sub-data in the first service data after the update processing does not belong to the abnormal service data, the preset time length is doubled to reacquire the data again, that is, the acquisition component 1 acquires the service data of the last 4 months as the first service data after the update processing, and so on, until there is a sub-data belonging to the abnormal service data in the first service data after the update processing, or it is determined that all sub-data of the component 1 does not belong to the abnormal service data.
[0057] In step S104, mean value calculation processing, median value calculation processing and standard deviation calculation processing are respectively performed according to the abnormal service data to obtain the abnormal mean value, the abnormal median value and the abnormal standard deviation of the preset component.
[0058] In a specific implementation, the mean value calculation processing, the median value calculation processing and the standard deviation calculation processing are respectively performed according to the abnormal service data to obtain the abnormal mean value, the abnormal median value and the abnormal standard deviation of the preset component, including the following steps: (a1) performing mean value calculation processing according to the abnormal service data to obtain the abnormal mean value of the preset component; (a2) performing median value calculation processing according to the abnormal service data to obtain the abnormal median value of the preset component; (a3) performing standard deviation calculation processing according to the abnormal service data to obtain the abnormal standard deviation of the preset component.
[0059] The steps (a1), (a2) and (a3) can be executed simultaneously, or the steps (a1), (a2) and (a3) can be executed sequentially, or the steps (a1), (a2) and (a3) can be executed sequentially according to other self-defined execution order. The execution order of the steps (a1), (a2) and (a3) is not specially limited in the embodiments of the present application.
[0060] The mean value is the average number, a statistical term, which represents the trend of a set of data. It is an index reflecting the trend of the data set.
[0061] The median value (Median) is also called the median, a special term in statistics, which is the number in the middle of a set of data arranged in order, representing a numerical value in a sample, population or probability distribution, which can divide the numerical set into equal upper and lower parts. For a finite number set, the median can be found by sorting all the observation values and finding the one in the middle. If there are an even number of observation values, the average of the two middle values is usually taken as the median.
[0062] Standard Deviation, a mathematical term, is the arithmetic square root of the arithmetic mean of the square of the deviation from the mean (i.e. variance). Standard deviation is also known as standard deviation or experimental standard deviation, and is most commonly used in probability statistics as a measure of the degree of dispersion of a statistical distribution. Standard deviation can reflect the dispersion degree of a data set. Two groups of data with the same mean may have different standard deviations.
[0063] In the case where the number of preset components is multiple, μ i represents the abnormal mean of the i-th preset component, M i represents the abnormal median of the i-th preset component, and σ i represents the abnormal standard deviation of the i-th preset component. i is a natural number greater than 0.
[0064] For example, the preset components include component 1, component 2 and component 3. The abnormal service data collected by component 1 is abnormal data 1; the abnormal service data collected by component 2 is abnormal data 2; and the abnormal service data collected by component 3 is abnormal data 3. The abnormal mean μ1, the abnormal median M1 and the abnormal standard deviation σ1 of component 1 are calculated according to abnormal data 1. The abnormal mean μ2, the abnormal median M2 and the abnormal standard deviation σ2 of component 2 are calculated according to abnormal data 2. The abnormal mean μ3, the abnormal median M3 and the abnormal standard deviation σ3 of component 3 are calculated according to abnormal data 3.
[0065] In step S106, the abnormal evaluation parameters of the preset components are determined according to the abnormal service data, the first service data, the abnormal mean, the abnormal median and the abnormal standard deviation.
[0066] The abnormal evaluation parameters of the preset components can be parameters that quantitatively describe the influence of the data collected by the preset components on the service system when the data is abnormal.
[0067] In a specific implementation, the abnormal evaluation parameters include a first evaluation parameter; the number of preset components is multiple; and the abnormal evaluation parameters of the preset components are determined according to the abnormal service data, the first service data, the abnormal mean, the abnormal median and the abnormal standard deviation, including: performing ratio calculation processing according to the data amount of the abnormal service data and the data amount of the first service data to obtain a first ratio of each preset component; performing ratio calculation processing according to the abnormal mean and the abnormal standard deviation to obtain a second ratio of each preset component; determining a maximum second ratio according to the numerical value size sorting result of the second ratio of each preset component; and determining the first evaluation parameter of each preset component according to the first ratio, the second ratio and the maximum second ratio of the preset component.
[0068] Exemplarily, the first ratio can be referred to as an abnormality ratio, and the second ratio can be referred to as a dispersion ratio. The abnormality ratio is a parameter quantitatively describing an abnormality degree of data collected by the preset component, and the greater the value of the abnormality ratio is, the more abnormal the monitoring object of the preset component is, and the more attention needs to be paid. The dispersion ratio is a parameter quantitatively describing a dispersion degree of abnormal business data, and the greater the value of the dispersion ratio is, the greater the change degree of the abnormal business data is.
[0069] The abnormality ratio can be calculated according to the following formula (1):
[0070] Abnormality ratio = Data amount of abnormal business data / Data amount of first business data (1)
[0071] The data amount of the abnormal business data can be the number of pieces of the abnormal business data, and the data amount of the first business data can be the number of pieces of the first business data.
[0072] It should be noted that the formula (1) is applicable to a case where the first business data includes the abnormal business data.
[0073] In a case where the first business data does not include the abnormal business data, the data amount of the first business data in the formula (1) can be replaced by the data amount of the first business data after the update processing.
[0074] In addition, it should be noted that, considering that the calculation of the first ratio does not need to use the abnormal mean value, the abnormal median value, and the abnormal standard deviation of the preset component, the execution order of the step of “performing ratio calculation processing according to the data amount of the abnormal business data and the data amount of the first business data to obtain the first ratio of each preset component” and the step S104 can be changed, that is, the first ratio is calculated first, and then the abnormal mean value, the abnormal median value, and the abnormal standard deviation are calculated. Alternatively, the step of “performing ratio calculation processing according to the data amount of the abnormal business data and the data amount of the first business data to obtain the first ratio of each preset component” and the step S104 can also be executed simultaneously.
[0075] The dispersion ratio can be calculated according to the following formula (2):
[0076] Dispersion ratio = Standard deviation σ / Mean value μ (2)
[0077] The standard deviation σ can be the abnormal standard deviation of the preset component, and the mean value μ can be the abnormal mean value of the preset component.
[0078] For example, the preset component includes component 1, component 2, and component 3. The dispersion ratio of component 1 is σ1 / μ1, the dispersion ratio of component 2 is σ2 / μ2, and the dispersion ratio of component 3 is σ3 / μ3.
[0079] The maximum second ratio can be determined according to a value size ordering result of each preset component second ratio, that is, each preset component second ratio is sequentially ordered from large to small according to the value size, a sorting result is obtained, the sorting result is determined as the value size ordering result, the maximum second ratio with the maximum value is determined based on the value size ordering result, and the maximum second ratio with the maximum value is taken as the maximum second ratio.
[0080] Exemplarily, the first evaluation parameter can be referred to as an adjustment value. The adjustment value is a parameter quantitatively describing the vulnerability of the monitoring object of the preset component itself. The greater the value of the adjustment value, the more vulnerable the monitoring object is. The smaller the value of the adjustment value, the stronger the monitoring object is.
[0081] For each preset component, the adjustment value can be calculated according to the following formula (3):
[0082] Adjustment value = first ratio * second ratio / maximum second ratio (3)
[0083] In the case where the number of preset components is one, for the preset component, the second ratio and the maximum second ratio are the same value, and then the adjustment value = first ratio * 1 = first ratio.
[0084] In the case where the number of preset components is greater than one, for each preset component, the value of the second ratio / the maximum second ratio is less than or equal to 1, and then the adjustment value is less than or equal to the first ratio.
[0085] It is considered that the greater the value of the adjustment value, the more vulnerable the monitoring object of the preset component corresponding to the adjustment value is, and then the greater the influence of the adjustment value on the risk prediction result when the network security situation is predicted and the risk is predicted based on the security situation information of the preset component in the future. The greater the value of the first ratio, the more abnormal the monitoring object of the preset component corresponding to the first ratio is, which needs to be focused on. Therefore, the adjustment value is proportional to the first ratio. In addition, in the case where the data collected by the preset component is abnormal, the greater the change degree of the abnormal business data, the greater the influence of the abnormal business data on the entire network security situation. Therefore, the second ratio is proportional to the adjustment value. In addition, the second ratio / the maximum second ratio quantitatively describes the abnormality degree of the preset component in all preset components, and therefore the second ratio / the maximum second ratio is also proportional to the adjustment value.
[0086] In a specific implementation, the abnormal evaluation parameter includes a second evaluation parameter; the abnormal evaluation parameter of the preset component is determined according to the abnormal business data, the first business data, the abnormal mean value, the abnormal median value and the abnormal standard deviation, including: performing mean value calculation processing according to the abnormal mean value and the abnormal median value to obtain the second evaluation parameter of the preset component.
[0087] Exemplarily, the second evaluation parameter can be referred to as a threshold value of the preset component.
[0088] The threshold value can be calculated according to the following formula (4) for each preset component:
[0089] Threshold value = (abnormal mean value + abnormal median value) / 2
[0090] The following can be combined with Figure 3 The generation process of the abnormal evaluation parameter is exemplarily described.
[0091] Figure 3 A sub-process flow chart for representing how to generate the abnormal evaluation parameter is provided in a risk prediction method of an embodiment of the present specification.
[0092] As Figure 3 shown, in step S302, abnormal data in the data of each type of security component is determined.
[0093] The security component can refer to the preset component described above. The abnormal data is abnormal business data.
[0094] In step S304, the abnormal ratio of each type of security component is calculated.
[0095] In step S306, the mean value, median value and standard deviation of the abnormal data of each type of security component are determined.
[0096] In step S308, the dispersion ratio of each type of security component is calculated.
[0097] In step S310, the maximum value of all dispersion ratios is determined.
[0098] In step S312, the adjustment value of each type of security component is calculated.
[0099] In step S314, the threshold value of each type of security component is determined.
[0100] Steps S302-S314 can refer to the corresponding description of steps S102-S106.
[0101] In step S108, the security posture information of the preset component is determined according to the abnormal evaluation parameter and the first business data.
[0102] The first business data can or can not include abnormal business data.
[0103] Based on the first business data, a data set including N elements can be formed, each element corresponding to a piece of monitoring data of the preset component, and each element in the data set is arranged in order from front to back according to the data collection time.
[0104] The security posture information is information describing the security state and the change trend of the whole network.
[0105] According to the abnormality evaluation parameter and the first service data, the security posture information of the preset component is determined, which can be determined according to the abnormality evaluation parameter, security posture sub-information of each element in the data set corresponding to the first service data. The security posture sub-information can describe the influence degree of the element on the preset component in the security posture dimension.
[0106] In a specific implementation, the abnormality evaluation parameter includes a first evaluation parameter and a second evaluation parameter; the first service data includes a plurality of sub-data; the security posture information includes security posture evaluation information of each sub-data; according to the abnormality evaluation parameter and the first service data, the security posture information of the preset component is determined, including: if the sub-data belongs to abnormal service data, the security posture evaluation information of the sub-data is determined according to the sub-data, the first evaluation parameter and the second evaluation parameter; if the sub-data does not belong to abnormal service data, the security posture evaluation information of the sub-data is determined according to the sub-data, the preset abnormality threshold and the first evaluation parameter.
[0107] The first service data includes a plurality of sub-data, that is, the data set corresponding to the first service data includes a plurality of elements.
[0108] According to the sub-data, the first evaluation parameter and the second evaluation parameter, the security posture evaluation information of the sub-data is determined, including: determining the difference between the sub-data and the threshold of the preset component, if the quotient between the difference and the threshold of the preset component is greater than the adjustment value of the preset component, the security posture evaluation information of the sub-data is determined as the first evaluation information, otherwise the security posture evaluation information of the sub-data is determined as the second evaluation information.
[0109] The first evaluation information can represent that the influence degree of the sub-data on the preset component in the security posture dimension is high; the second evaluation information can represent that the influence degree of the sub-data on the preset component in the security posture dimension is medium.
[0110] Exemplarily, for an element d in the data set corresponding to the component 1, if the element d belongs to abnormal service data, the difference between the element d and the threshold of the component 1 is determined, if the quotient between the difference and the threshold of the component 1 is greater than the adjustment value of the component 1, the influence degree corresponding to the element d is determined as high, otherwise the influence degree corresponding to the element d is determined as medium.
[0111] According to the sub-data, the preset abnormality threshold and the first evaluation parameter, the security posture evaluation information of the sub-data is determined, including: determining the difference between the business abnormality threshold and the sub-data, if the quotient between the difference and the business abnormality threshold is less than the adjustment value of the preset component, the security posture evaluation information of the sub-data is determined as the third evaluation information, otherwise the security posture evaluation information of the sub-data is determined as the first evaluation information.
[0112] The third evaluation information can represent that the influence degree of the sub-data on the preset component in the security situation dimension is low.
[0113] For example, for an element d in the data set corresponding to component 1, if the element d does not belong to abnormal business data, the difference between the business exception threshold of component 1 and the element d is determined, and if the quotient between the difference and the business exception threshold of component 1 is less than the adjustment value of component 1, it is determined that the influence degree corresponding to the element d is low, otherwise it is determined that the influence degree corresponding to the element d is high.
[0114] By sequentially processing each element in the data set corresponding to the first business data, a security situation information set of the preset component can be obtained, for example, the security situation information set of component 1 is {high, high, medium, low, low, …}. Each element in the data set corresponding to the first business data has a one-to-one correspondence with each element in the security situation information set, and thus the number of elements in the security situation information set is the same as the number of elements in the data set corresponding to the first business data.
[0115] In the case where the number of preset components is multiple and the data collection frequency of each preset component is the same, the number of first business data collected by each preset component is the same, and thus the number of elements in the security situation information set of each preset component is also the same.
[0116] The following can be combined Figure 4 to illustrate the generation process of security situation information. Figure 4 A sub-process diagram illustrating how to generate security situation information is provided in a risk prediction method of an embodiment of the present specification.
[0117] As Figure 4 shown, in step S402, the monitoring data of the security component is grouped into a set, each element in the set is a monitoring data, and the elements in the set are sorted by data collection time.
[0118] The security component is a preset component, and the monitoring data of the security component is the first business data.
[0119] In step S404, each element in the set is sequentially selected.
[0120] In step S406, the influence degree of each element in the set is determined, and a security situation influence degree set of various security components is obtained.
[0121] The influence degree of each element is the influence degree of the element on the preset component in the security situation dimension.
[0122] The security situation influence degree set can refer to the security situation information set described above.
[0123] In step S110, risk prediction processing is performed on the first service data according to the abnormality evaluation parameter and the security posture information, and a risk prediction result is obtained.
[0124] The risk prediction processing in the embodiment of the application can be network security posture prediction processing.
[0125] The risk prediction processing on the first service data according to the abnormality evaluation parameter and the security posture information to obtain the risk prediction result can be that the security posture prediction values of the first service data at a plurality of preset risk levels are calculated according to the abnormality evaluation parameter and the security posture information, the security posture prediction values at the plurality of preset risk levels are sorted according to the numerical values, the security posture prediction value with the largest numerical value is determined based on the sorting result, and then the preset risk level corresponding to the security posture prediction value with the largest numerical value is determined as a target risk level, and the target risk level is taken as the risk prediction result of the first service data.
[0126] In the case where the target risk level belongs to the preset alarm level set, risk alarm processing is performed; in the case where the target risk level does not belong to the preset alarm level set, no operation is performed.
[0127] For example, in the case where the target risk level is “high”, risk alarm processing of a first alarm type is performed; in the case where the target risk level is “medium”, risk alarm processing of a second alarm type is performed; and in the case where the target risk level is “low”, no risk alarm processing is performed.
[0128] The first alarm type and the second alarm type can be two different alarm types configured in advance. “First” and “second” are only used to distinguish the two alarm types and do not have actual meanings.
[0129] In one specific implementation, the risk prediction processing on the first service data according to the abnormality evaluation parameter and the security posture information to obtain the risk prediction result includes: determining risk prediction weight information of the preset component according to the security posture evaluation information of each sub-data; performing mean value calculation processing on each sub-data to obtain a service data mean value of the preset component; and performing risk prediction processing on the first service data according to the risk prediction weight information, the first evaluation parameter, the second evaluation parameter, and the service data mean value to obtain the risk prediction result.
[0130] The determination of the risk prediction weight information of the preset component according to the security posture evaluation information of each sub-data can be that the risk prediction weight information of the preset component at a plurality of preset risk levels is determined according to the security posture evaluation information of each sub-data, for example, “high” weight, “medium” weight, and “low” weight, etc.
[0131] In a case where the number of preset components is multiple, the risk prediction weight information of each preset component at the same preset risk level can be the same or different.
[0132] The mean value of the business data of the preset component is obtained by performing mean value calculation processing on each sub-data.
[0133] The risk prediction processing on the first business data according to the risk prediction weight information, the first evaluation parameter, the second evaluation parameter and the mean value of the business data obtains a risk prediction result, which can include: for each preset risk level, calculating according to the first evaluation parameter, the second evaluation parameter, the mean value of the business data and the risk prediction weight information corresponding to the preset risk level to obtain a security posture prediction value of the preset risk level; and determining the preset risk level with the largest security posture prediction value as the risk prediction result.
[0134] In a specific implementation, the number of preset components is multiple; each sub-data in the first business data is arranged in time sequence; the risk prediction weight information of the preset component is determined according to the security posture evaluation information of each sub-data, which includes: determining a security posture initial value according to the security posture evaluation information of the first sub-data in the first business data collected by each preset component and the number of preset components; determining a security posture intermediate value according to the security posture evaluation information of each sub-data in the first business data collected by each preset component and the number of preset components; and determining the risk prediction weight information of the preset component according to the security posture initial value and the security posture intermediate value.
[0135] The security posture information set of each preset component can include the influence degree of each monitoring data in the first business data collected by the preset component on the preset component in the security posture dimension, for example, the security posture information set of component 1 is {high, high, medium, low, low, …}.
[0136] The security posture initial value can include the influence degree initial value corresponding to multiple preset risk levels, for example, a “high” initial value, a “medium” initial value and a “low” initial value.
[0137] According to the security situation evaluation information of the first sub-data in the first service data collected by each preset component and the number of preset components, the initial value of the security situation is determined, including: according to the preset component number of the first evaluation information of the security situation evaluation information of the first sub-data and the total number of preset components, ratio calculation processing is performed to obtain the initial value of the influence degree corresponding to the first evaluation information; according to the preset component number of the second evaluation information of the security situation evaluation information of the first sub-data and the total number of preset components, ratio calculation processing is performed to obtain the initial value of the influence degree corresponding to the second evaluation information; according to the preset component number of the third evaluation information of the security situation evaluation information of the first sub-data and the total number of preset components, ratio calculation processing is performed to obtain the initial value of the influence degree corresponding to the third evaluation information.
[0138] For example, the "high" initial value = the number of preset components whose first element in the security situation information set of each preset component is "high" / the total number of preset components.
[0139] The "medium" initial value = the number of preset components whose first element in the security situation information set of each preset component is "medium" / the total number of preset components.
[0140] The "low" initial value = the number of preset components whose first element in the security situation information set of each preset component is "low" / the total number of preset components.
[0141] The security situation intermediate value can represent the influence degree between any two adjacent sub-data in the first service data, and the number of types of the security situation intermediate value can be determined by the preset risk level, for example, "high-high" influence degree, "medium-high" influence degree, "low-high" influence degree, "high-medium" influence degree, "medium-medium" influence degree, "low-medium" influence degree, "high-low" influence degree, "medium-low" influence degree, and "low-low" influence degree. Take "high-low" as an example to illustrate the security situation intermediate value, wherein the first word is the influence degree corresponding to the former one of the two adjacent sub-data, and the second word is the influence degree corresponding to the latter one of the two adjacent sub-data.
[0142] According to the security situation evaluation information of each sub-data in the first service data collected by each preset component and the number of preset components, a security situation intermediate value is determined, including: according to the number of preset components whose i-th sub-data security situation evaluation information is the first evaluation information and whose i+1-th sub-data security situation evaluation information is the first evaluation information, and the total number of preset components, a ratio calculation is performed to obtain a first intermediate value; according to the number of preset components whose i-th sub-data security situation evaluation information is the second evaluation information and whose i+1-th sub-data security situation evaluation information is the first evaluation information, and the total number of preset components, a ratio calculation is performed to obtain a second intermediate value; according to the number of preset components whose i-th sub-data security situation evaluation information is the third evaluation information and whose i+1-th sub-data security situation evaluation information is the first evaluation information, and the total number of preset components, a ratio calculation is performed to obtain a third intermediate value; according to the number of preset components whose i-th sub-data security situation evaluation information is the first evaluation information and whose i+1-th sub-data security situation evaluation information is the second evaluation information, and the total number of preset components, a ratio calculation is performed to obtain a fourth intermediate value; according to the number of preset components whose i-th sub-data security situation evaluation information is the second evaluation information and whose i+1-th sub-data security situation evaluation information is the second evaluation information, and the total number of preset components, a ratio calculation is performed to obtain a fifth intermediate value; according to the number of preset components whose i-th sub-data security situation evaluation information is the third evaluation information and whose i+1-th sub-data security situation evaluation information is the second evaluation information, and the total number of preset components, a ratio calculation is performed to obtain a sixth intermediate value; according to the number of preset components whose i-th sub-data security situation evaluation information is the first evaluation information and whose i+1-th sub-data security situation evaluation information is the third evaluation information, and the total number of preset components, a ratio calculation is performed to obtain a seventh intermediate value; according to the number of preset components whose i-th sub-data security situation evaluation information is the second evaluation information and whose i+1-th sub-data security situation evaluation information is the third evaluation information, and the total number of preset components, a ratio calculation is performed to obtain an eighth intermediate value; according to the number of preset components whose i-th sub-data security situation evaluation information is the third evaluation information and whose i+1-th sub-data security situation evaluation information is the third evaluation information, and the total number of preset components, a ratio calculation is performed to obtain a ninth intermediate value. Wherein, i is a natural number greater than 0.
[0143] The influence degree between sub-data 1 and sub-data 2 in the first service data is taken as an example to illustrate how to calculate the influence degree between two adjacent sub-data.
[0144] The "high" initial value = the number of the first element being "high" in the security situation information set of each preset component / the total number of preset components.
[0145] The influence degree of "high-high" = the number of preset components whose first element in the security posture information set is "high" and whose second element is "high" in all preset components / the total number of preset components.
[0146] The influence degree of "medium-high" = the number of preset components whose first element in the security posture information set is "medium" and whose second element is "high" in all preset components / the total number of preset components.
[0147] The influence degree of "low-high" = the number of preset components whose first element in the security posture information set is "low" and whose second element is "high" in all preset components / the total number of preset components.
[0148] The influence degree of "high-medium" = the number of preset components whose first element in the security posture information set is "high" and whose second element is "medium" in all preset components / the total number of preset components.
[0149] The influence degree of "medium-medium" = the number of preset components whose first element in the security posture information set is "medium" and whose second element is "medium" in all preset components / the total number of preset components.
[0150] The influence degree of "low-medium" = the number of preset components whose first element in the security posture information set is "low" and whose second element is "medium" in all preset components / the total number of preset components.
[0151] The influence degree of "high-low" = the number of preset components whose first element in the security posture information set is "high" and whose second element is "low" in all preset components / the total number of preset components.
[0152] The influence degree of "medium-low" = the number of preset components whose first element in the security posture information set is "medium" and whose second element is "low" in all preset components / the total number of preset components.
[0153] The influence degree of "low-low" = the number of preset components whose first element in the security posture information set is "low" and whose second element is "low" in all preset components / the total number of preset components.
[0154] Referring to the calculation manner of the influence degree between the sub-data 1 and the sub-data 2 in the first service data, the influence degrees between the sub-data 2 and the sub-data 3, the influence degrees between the sub-data 3 and the sub-data 4,..., and the influence degrees between the sub-data n-1 and the sub-data n can be calculated. Wherein, n is a natural number greater than 1, and is used to represent the total number of elements in the security posture information set.
[0155] The security posture intermediate value can include an influence degree between sub-data 1 and sub-data 2, an influence degree between sub-data 2 and sub-data 3, an influence degree between sub-data 3 and sub-data 4, …, an influence degree between sub-data n-1 and sub-data n in the first business data collected by each preset component.
[0156] According to the security posture initial value and the security posture intermediate value, the risk prediction weight information of the preset component can be determined according to the security posture initial value and the security posture intermediate value, and the risk prediction weight information corresponding to each preset risk level in the plurality of preset risk levels of the preset component can be determined.
[0157] Exemplarily, in the case that the number of preset components is a plurality, for each preset component, the calculation process of the risk prediction weight information is as follows:
[0158] (b1) calculating a first "high" value = (an influence degree of "high-high" between sub-data 1 and sub-data 2 / the "high" initial value) + (an influence degree of "medium-high" between sub-data 1 and sub-data 2 / the "medium" initial value) + (an influence degree of "low-high" between sub-data 1 and sub-data 2 / the "low" initial value)
[0159] a first "medium" value = (an influence degree of "high-medium" between sub-data 1 and sub-data 2 / the "high" initial value) + (an influence degree of "medium-medium" between sub-data 1 and sub-data 2 / the "medium" initial value) + (an influence degree of "low-medium" between sub-data 1 and sub-data 2 / the "low" initial value)
[0160] a first "low" value = (an influence degree of "high-low" between sub-data 1 and sub-data 2 / the "high" initial value) + (an influence degree of "medium-low" between sub-data 1 and sub-data 2 / the "medium" initial value) + (an influence degree of "low-low" between sub-data 1 and sub-data 2 / the "low" initial value)
[0161] (b2) calculating a second "high" value = (an influence degree of "high-high" between sub-data 2 and sub-data 3 / the first "high" value) + (an influence degree of "medium-high" between sub-data 2 and sub-data 3 / the first "medium" value) + (an influence degree of "low-high" between sub-data 2 and sub-data 3 / the first "low" value)
[0162] a second "medium" value = (an influence degree of "high-medium" between sub-data 2 and sub-data 3 / the first "high" value) + (an influence degree of "medium-medium" between sub-data 2 and sub-data 3 / the first "medium" value) + (an influence degree of "low-medium" between sub-data 2 and sub-data 3 / the first "low" value)
[0163] The 2nd "low" value = (the influence degree of "high-low" between the 2nd sub-data and the 3rd sub-data / the 1st "high" value) + (the influence degree of "medium-low" between the 2nd sub-data and the 3rd sub-data / the 1st "medium" value) + (the influence degree of "low-low" between the 2nd sub-data and the 3rd sub-data / the 1st "low" value)
[0164] (b3) calculating the i-th "high" value = (the influence degree of "high-high" between the i-th sub-data and the (i+1)-th sub-data / the (i-1)-th "high" value) + (the influence degree of "medium-high" between the i-th sub-data and the (i+1)-th sub-data / the (i-1)-th "medium" value) + (the influence degree of "low-high" between the i-th sub-data and the (i+1)-th sub-data / the (i-1)-th "low" value)
[0165] The i-th "medium" value = (the influence degree of "high-medium" between the i-th sub-data and the (i+1)-th sub-data / the (i-1)-th "high" value) + (the influence degree of "medium-medium" between the i-th sub-data and the (i+1)-th sub-data / the (i-1)-th "medium" value) + (the influence degree of "low-medium" between the i-th sub-data and the (i+1)-th sub-data / the (i-1)-th "low" value)
[0166] The i-th "low" value = (the influence degree of "high-low" between the i-th sub-data and the (i+1)-th sub-data / the (i-1)-th "high" value) + (the influence degree of "medium-low" between the i-th sub-data and the (i+1)-th sub-data / the (i-1)-th "medium" value) + (the influence degree of "low-low" between the i-th sub-data and the (i+1)-th sub-data / the (i-1)-th "low" value)
[0167] Wherein, i = 3, 4, …, n-1. n is a natural number greater than 1, used to represent the total number of elements of the security posture information set.
[0168] (b4) determining the (n-1)-th "high" value as the risk prediction weight information corresponding to the preset risk level "high", i.e. the "high" weight value; determining the (n-1)-th "medium" value as the risk prediction weight information corresponding to the preset risk level "medium", i.e. the "medium" weight value; and determining the (n-1)-th "low" value as the risk prediction weight information corresponding to the preset risk level "low", i.e. the "low" weight value.
[0169] The following can be combined Figure 5 to illustrate the processing flow of how to generate the risk prediction weight information. Figure 5 A sub-process flow chart illustrating how to generate the risk prediction weight information is provided in a risk prediction method of an embodiment of the present specification.
[0170] As Figure 5 shown in FIG. 5, in step S502, the influence degree initial value is determined according to the influence degree set of each type of security component.
[0171] The influence degree set of the security component, i.e. the security posture information set of the preset component.
[0172] Step S504, determine the influence degree between each element.
[0173] The influence degree between each element can refer to the intermediate value of the safety situation in the foregoing.
[0174] Step S506, determine the "high" weight, "medium" weight, and "low" weight.
[0175] In a specific implementation, the number of preset components is multiple; each sub-data in the first business data is arranged according to a time collection sequence; the risk prediction weight information includes weight values of multiple preset risk levels; and the risk prediction processing is performed on the first business data according to the risk prediction weight information, the first evaluation parameter, the second evaluation parameter, and the business data mean value to obtain a risk prediction result, including: determining a risk prediction value of each preset risk level of each preset component according to the weight value of each preset risk level, the first evaluation parameter, the second evaluation parameter, the business data mean value, and the last sub-data in the first business data; performing mean value calculation processing on the risk prediction value of each preset component for each preset risk level to obtain a risk prediction average value of the preset risk level; and determining the preset risk level with the maximum risk prediction average value as the risk prediction result.
[0176] The risk prediction weight information includes weight values of multiple preset risk levels. Exemplarily, the risk prediction weight information includes a "high" weight value, a "medium" weight value, and a "low" weight value.
[0177] For each preset component, the calculation process of the risk prediction value corresponding to the preset risk level "high" can refer to the following formula (5):
[0178] Risk prediction value corresponding to preset risk level "high" = "high" weight value * last sub-data in first business data * (1+adjustment value) / max{business data mean value, threshold value} (5)
[0179] The threshold value is the second evaluation parameter described above. max{business data mean value, threshold value} refers to the one with the maximum value between the business data mean value and the threshold value.
[0180] For each preset component, the calculation process of the risk prediction value corresponding to the preset risk level "medium" can refer to the following formula (6):
[0181] Risk prediction value corresponding to preset risk level "medium" = "medium" weight value * last sub-data in first business data * (1+adjustment value) / max{business data mean value, threshold value} (6)
[0182] The threshold value is the second evaluation parameter mentioned above. max{the average of the service data, the threshold value} refers to the larger one of the average of the service data and the threshold value.
[0183] For each preset component, the calculation process of the risk prediction value corresponding to the preset risk level "low" can refer to the following formula (7):
[0184] Risk prediction value corresponding to preset risk level "low" = "low" weight value * last sub-data in first service data * (1 + adjustment value) / max{average of service data, threshold value} (7)
[0185] The threshold value is the second evaluation parameter mentioned above. max{the average of the service data, the threshold value} refers to the larger one of the average of the service data and the threshold value.
[0186] In the case where the number of preset components is multiple, for each preset risk level, the average value of the risk prediction value of each preset component is calculated to obtain the average risk prediction value of the preset risk level, and the preset risk level with the maximum average risk prediction value is determined as the risk prediction result.
[0187] For example, the preset components include component 1, component 2 and component 3, and the preset risk levels include "high", "medium" and "low".
[0188] The risk prediction value corresponding to the preset risk level "high" of component 1 is A1, the risk prediction value corresponding to the preset risk level "high" of component 2 is A2, and the risk prediction value corresponding to the preset risk level "high" of component 3 is A3. Then, the average value S1 of the preset risk level "high" is obtained by performing average calculation on A1, A2 and A3.
[0189] The risk prediction value corresponding to the preset risk level "medium" of component 1 is B1, the risk prediction value corresponding to the preset risk level "medium" of component 2 is B2, and the risk prediction value corresponding to the preset risk level "medium" of component 3 is B3. Then, the average value S2 of the preset risk level "medium" is obtained by performing average calculation on B1, B2 and B3.
[0190] The risk prediction value corresponding to the preset risk level "low" of component 1 is C1, the risk prediction value corresponding to the preset risk level "low" of component 2 is C2, and the risk prediction value corresponding to the preset risk level "low" of component 3 is C3. Then, the average value S3 of the preset risk level "low" is obtained by performing average calculation on C1, C2 and C3.
[0191] S1 > S2 > S3 > 0, then S1 is the maximum risk prediction average value, and the preset risk level "high" corresponding to S1 is determined as the risk prediction result.
[0192] In summary, the risk prediction method provided by the embodiment can generate an abnormal evaluation parameter of a preset component based on abnormal business data, first business data, an abnormal mean value, an abnormal median value and an abnormal standard deviation in the case that different dimensions of business data features collected by different preset components are different, and then convert the business data of different dimensions into a risk prediction result of an overall network in the process of generating security situation information and predicting risks by using the security situation information, thereby improving the accuracy of risk prediction.
[0193] Another risk prediction method is also provided by the embodiment of the application based on the same technical concept. Figure 6 Another risk prediction method processing flowchart is provided by an embodiment of the present specification.
[0194] In step S602, the monitoring data of all types of security components is obtained.
[0195] In step S604, the threshold value and the adjustment value of each type of security component are determined.
[0196] In step S606, the security situation influence degree set of each type of security component is determined according to the threshold value and the adjustment value of each type of security component.
[0197] In step S608, the network security situation is predicted according to the security situation influence degree set of each type of security component.
[0198] In step S610, the network "high" risk value, "medium" risk value and "low" risk value are predicted.
[0199] The "high" risk value can refer to the risk prediction value corresponding to the preset risk level "high" in the embodiment. Figure 1 The "medium" risk value can refer to the risk prediction value corresponding to the preset risk level "medium" in the embodiment.
[0200] The "low" risk value can refer to the risk prediction value corresponding to the preset risk level "low" in the embodiment. Figure 1 The "low" risk value can refer to the risk prediction value corresponding to the preset risk level "low" in the embodiment.
[0201] The "low" risk value can refer to the risk prediction value corresponding to the preset risk level "low" in the embodiment. Figure 1 The "low" risk value can refer to the risk prediction value corresponding to the preset risk level "low" in the embodiment.
[0202] In step S612, the "high" risk value, "medium" risk value and "low" risk value of the network are predicted.
[0203] Since the technical concept is the same, the embodiment is described more simply, and the related parts can be referred to the corresponding description of the method embodiment provided above.
[0204] Figure 7 A risk prediction device schematic diagram provided by an embodiment of the present application is shown in FIG. 1. Figure 7As shown, the device comprises:
[0205] The data determination module 702 is configured to acquire first service data collected by a preset component, and determine abnormal service data collected by the preset component according to the first service data.
[0206] The data calculation module 704 is configured to perform mean value calculation processing, median value calculation processing and standard deviation calculation processing on the abnormal service data respectively, to obtain abnormal mean value, abnormal median value and abnormal standard deviation of the preset component.
[0207] The parameter determination module 706 is configured to determine an abnormal evaluation parameter of the preset component according to the abnormal service data, the first service data, the abnormal mean value, the abnormal median value and the abnormal standard deviation.
[0208] The information determination module 708 is configured to determine security situation information of the preset component according to the abnormal evaluation parameter and the first service data.
[0209] The risk prediction module 710 is configured to perform risk prediction processing on the first service data according to the abnormal evaluation parameter and the security situation information, to obtain a risk prediction result.
[0210] The risk prediction device provided by the embodiment of the present specification can implement each process in the foregoing method embodiment, and achieve the same functions and effects, which are not repeated here.
[0211] Further, one embodiment of the present specification also provides a risk prediction device, Figure 8 A structural schematic diagram of a risk prediction device provided by an embodiment of the present specification is shown in Figure 8 As shown, the device comprises a memory 801, a processor 802, a bus 803 and a communication interface 804. The memory 801, the processor 802 and the communication interface 804 communicate through the bus 803. The communication interface 804 can include an input and output interface, including but not limited to a keyboard, a mouse, a display, a microphone, a loudspeaker, etc.
[0212] Figure 8 In the embodiment, the memory 801 stores computer executable instructions that can run on the processor 802. When the computer executable instructions are executed by the processor 802, the following processes are implemented:
[0213] Acquire first service data collected by a preset component, and determine abnormal service data collected by the preset component according to the first service data;
[0214] The mean value calculation processing, the median value calculation processing and the standard deviation calculation processing are performed on the abnormal business data respectively to obtain abnormal mean value, abnormal median value and abnormal standard deviation of the preset component;
[0215] The abnormal evaluation parameter of the preset component is determined according to the abnormal business data, the first business data, the abnormal mean value, the abnormal median value and the abnormal standard deviation;
[0216] The security situation information of the preset component is determined according to the abnormal evaluation parameter and the first business data;
[0217] The risk prediction result is obtained by performing the risk prediction processing on the first business data according to the abnormal evaluation parameter and the security situation information.
[0218] The risk prediction device provided by the embodiment of the present specification can realize each process in the foregoing method embodiments and achieve the same functions and effects, which are not repeated here.
[0219] Further, another embodiment of the present specification further provides a computer readable storage medium for storing computer executable instructions, wherein the computer executable instructions are executed by a processor to realize the following processes:
[0220] The first business data collected by a preset component is obtained, and abnormal business data collected by the preset component is determined according to the first business data;
[0221] The mean value calculation processing, the median value calculation processing and the standard deviation calculation processing are performed on the abnormal business data respectively to obtain abnormal mean value, abnormal median value and abnormal standard deviation of the preset component;
[0222] The abnormal evaluation parameter of the preset component is determined according to the abnormal business data, the first business data, the abnormal mean value, the abnormal median value and the abnormal standard deviation;
[0223] The security situation information of the preset component is determined according to the abnormal evaluation parameter and the first business data;
[0224] The risk prediction result is obtained by performing the risk prediction processing on the first business data according to the abnormal evaluation parameter and the security situation information.
[0225] The computer readable storage medium includes a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0226] The computer readable storage medium provided by an embodiment of the specification can realize the various processes in the foregoing method embodiments and achieve the same functions and effects, which are not repeated here.
[0227] Those skilled in the art should understand that embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer readable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) containing computer usable program code.
[0228] The present application is described with reference to flowcharts and / or block diagrams of the method, device (system), and computer program product according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing apparatus produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 means for performing the functions specified in the flowchart
[0229] These computer program instructions can also be stored in a computer readable memory that can direct the computer or other programmable data processing apparatus to work in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including instruction means, which implements the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 means for performing the functions specified in the flowchart
[0230] These computer program instructions can also be loaded into a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable data processing apparatus to produce a computer implemented process, so that the instructions executed on the computer or other programmable data processing apparatus provide a process for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 means for performing the functions specified in the flowchart
[0231] In a typical configuration, the computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memories.
[0232] Memory can include, without being limited to, non-persistent memory, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory. Memory is an example of computer readable storage media.
[0233] Computer readable storage media includes permanent and non-permanent, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Examples of computer readable storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD), or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information accessible to a computing device. According to the definition herein, computer readable storage media does not include transitory media, such as modulated data signals and carrier waves.
[0234] It should also be noted that the terms "comprising," "including," or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. Without limitation, an element preceded by "comprises a" does not, without more constraints, foreclose the existence of additional identical elements in the process, method, article, or apparatus that comprises the identified element.
[0235] Those skilled in the art will understand that embodiments of the present application can be provided as a method, a system or a computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) embodying computer readable program code.
[0236] The embodiments described above are only used to illustrate the present application and not intended to limit the present application. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application should be included in the scope of claims of the present application.
Claims
1. A risk prediction method, characterized by, The method comprises: acquiring first service data collected by a preset component, and determining abnormal service data collected by the preset component according to the first service data; the number of the preset components is multiple; the first service data comprises multiple sub-data; performing mean value calculation processing, median value calculation processing and standard deviation calculation processing on the abnormal service data respectively to obtain abnormal mean value, abnormal median value and abnormal standard deviation of the preset component; determining an abnormal evaluation parameter of the preset component according to the abnormal service data, the first service data, the abnormal mean value, the abnormal median value and the abnormal standard deviation; the abnormal evaluation parameter comprises a first evaluation parameter and a second evaluation parameter; determining security situation information of the preset component according to the abnormal evaluation parameter and the first service data; the security situation information comprises security situation evaluation information of each sub-data; performing risk prediction processing on the first service data according to the abnormal evaluation parameter and the security situation information to obtain a risk prediction result; wherein the determining of the abnormal evaluation parameter of the preset component according to the abnormal service data, the first service data, the abnormal mean value, the abnormal median value and the abnormal standard deviation comprises: performing ratio calculation processing on the data quantity of the abnormal service data and the data quantity of the first service data to obtain a first ratio of each preset component; performing ratio calculation processing on the abnormal mean value and the abnormal standard deviation to obtain a second ratio of each preset component; determining a maximum second ratio according to the numerical size sorting result of the second ratio of each preset component; for each preset component, determining the first evaluation parameter of the preset component according to the first ratio, the second ratio and the maximum second ratio of the preset component; performing mean value calculation processing on the abnormal mean value and the abnormal median value to obtain the second evaluation parameter of the preset component; the determining of the security situation information of the preset component according to the abnormal evaluation parameter and the first service data comprises: if the sub-data belongs to the abnormal service data, determining the security situation evaluation information of the sub-data according to the sub-data, the first evaluation parameter and the second evaluation parameter; if the sub-data does not belong to the abnormal service data, determining the security situation evaluation information of the sub-data according to the sub-data, a preset abnormal threshold and the first evaluation parameter.
2. The method of claim 1, wherein, the performing of the risk prediction processing on the first service data according to the abnormal evaluation parameter and the security situation information to obtain the risk prediction result comprises: determining risk prediction weight information of the preset component according to the security situation evaluation information of each sub-data; performing mean value calculation processing on each sub-data to obtain service data mean value of the preset component; performing risk prediction processing on the first service data according to the risk prediction weight information, the first evaluation parameter, the second evaluation parameter and the service data mean value to obtain the risk prediction result.
3. The method of claim 2, wherein, Each of the sub-data in the first business data is arranged according to time collection sequence; The risk prediction weight information of the preset component is determined according to the security situation evaluation information of each of the sub-data and the number of the preset components. An initial value of a security situation is determined according to the security situation evaluation information of the first sub-data in the first business data collected by each of the preset components and the number of the preset components. An intermediate value of a security situation is determined according to the security situation evaluation information of each of the sub-data in the first business data collected by each of the preset components and the number of the preset components. The risk prediction weight information of the preset component is determined according to the initial value of the security situation and the intermediate value of the security situation.
4. The method of claim 2, wherein, Each of the sub-data in the first business data is arranged according to time collection sequence; the risk prediction weight information includes weight values of multiple preset risk levels; the risk prediction result is obtained by performing risk prediction processing on the first business data according to the risk prediction weight information, the first evaluation parameter, the second evaluation parameter and the business data mean, including: A risk prediction value of each of the preset risk levels for each of the preset components is determined according to the weight value of each of the preset risk levels, the first evaluation parameter, the second evaluation parameter, the business data mean and the last sub-data in the first business data. For each of the preset risk levels, a risk prediction average value of the preset risk level is obtained by performing mean calculation processing on the risk prediction values of each of the preset components. The preset risk level with the maximum risk prediction average value is determined as the risk prediction result.
5. A risk prediction apparatus characterized by comprising: The data determination module is configured to acquire first business data collected by a preset component, and determine abnormal business data collected by the preset component according to the first business data. The number of the preset components is multiple; the first business data includes multiple sub-data. The data calculation module is configured to perform mean calculation processing, median value calculation processing and standard deviation calculation processing on the abnormal business data respectively, and obtain abnormal mean, abnormal median value and abnormal standard deviation of the preset component. The parameter determination module is configured to determine abnormal evaluation parameters of the preset component according to the abnormal business data, the first business data, the abnormal mean, the abnormal median value and the abnormal standard deviation; the abnormal evaluation parameters include first evaluation parameters and second evaluation parameters. The information determination module is configured to determine security situation information of the preset component according to the abnormal evaluation parameters and the first business data; the security situation information includes security situation evaluation information of each of the sub-data. The risk prediction module is configured to perform risk prediction processing on the first business data according to the abnormal evaluation parameters and the security situation information, and obtain a risk prediction result. The parameter determination module is specifically configured to: perform ratio calculation processing on the data volume of the abnormal service data and the data volume of the first service data to obtain a first ratio of each of the preset components; perform ratio calculation processing on the abnormal mean and the abnormal standard deviation to obtain a second ratio of each of the preset components; determine a maximum second ratio according to a numerical size sorting result of the second ratio of each of the preset components; for each of the preset components, determine the first evaluation parameter of the preset component according to the first ratio, the second ratio of the preset component, and the maximum second ratio; and perform mean calculation processing on the abnormal mean and the abnormal median value to obtain a second evaluation parameter of the preset component; The information determination module is specifically configured to: if the sub-data belongs to the abnormal service data, determine security posture evaluation information of the sub-data according to the sub-data, the first evaluation parameter, and the second evaluation parameter; and if the sub-data does not belong to the abnormal service data, determine security posture evaluation information of the sub-data according to the sub-data, a preset abnormal threshold, and the first evaluation parameter.
6. A risk prediction device, characterized by, The computer executable instructions, when executed by the processor, can implement the steps of the risk prediction method of any one of claims 1-4.
7. A computer-readable storage medium having stored computer-executable instructions, the computer-executable instructions comprising: The computer executable instructions, when executed by the processor, can implement the steps of the risk prediction method of any one of claims 1-4.
Citation Information
Patent Citations
Abnormal service monitoring method and device
CN110033130A
Scoring method and device based on standard normal distribution, equipment and storage medium
CN112258095A